
AI-generated editorial illustration by CyberShitty. Not a photograph or a document from the organisations named.
The state-owned lender told stock exchanges it is investigating a possible business email compromise after an anonymous claim of data access. Claims that about 1TB of bank files were taken remain unverified.
01 / What happened
Bank of Baroda, one of India's largest state-owned lenders, told the BSE and the National Stock Exchange (NSE) on the evening of 27 July 2026 that it was dealing with a cyber-security incident. In a disclosure under Regulation 30 of SEBI's Listing Obligations and Disclosure Requirements (LODR) Regulations, the bank said it had received a communication from an anonymous source claiming access to certain data.
The bank said it activated its incident response and containment protocols and engaged an independent CERT-In empanelled cyber-security agency to investigate the nature and extent of the alleged compromise. Based on preliminary findings, it said the incident had been identified as a potential business email compromise and was not expected to have any material impact on its operations, financial performance or business continuity. It said core business functions continued to operate normally and a detailed assessment was under way.
Earlier that day, NSE had asked the bank to clarify a news item saying Bank of Baroda data had reportedly been leaked on the dark web. The bank's reply, posted on 28 July, attached the same disclosure. The Record reported on 28 July that the bank said an employee's email account had been compromised, giving unauthorised access to certain data, and that its core banking systems were not accessed.
02 / Why it matters
Bank of Baroda serves a large base of retail, NRI and corporate customers. Documents that pass through staff mailboxes, such as loan files, account-opening forms and audit reports, can be used for targeted fraud even when core banking systems are untouched.
A compromised mailbox does not need to reach the core banking system to leak data that fraudsters can use.
The bank has not said how many customers, if any, are affected, or what data the attacker actually saw. Its exchange filings up to late September show no further update on the incident.
03 / Who is exposed
The bank has not identified which data was accessed. According to press reports, the material offered online was claimed to include:
- customer identity and account-opening (KYC) documents
- loan applications and appraisal records
- internal audit and branch reports
- internal emails and communications
Moneylife reported that the listing also claimed to contain Aadhaar numbers, NetBanking user details and NRI and corporate banking records. None of these claims has been verified, and the bank has not confirmed that customer data left its systems.
04 / Confirmed vs. claimed
Confirmed (bank's exchange filing, 27 July 2026): a cyber-security incident; an anonymous communication claiming access to data; a CERT-In empanelled agency engaged to investigate; a preliminary finding of potential business email compromise; no expected material impact; core functions operating normally.
Claimed / unconfirmed: that about 1TB of bank data was stolen and published or offered for sale. The Record said the data was advertised on a darknet marketplace and that its authenticity could not be independently verified. Gulf News reported that no group had publicly claimed responsibility, that some researchers linked the listing to an actor calling itself TripleX, and that the size of the dataset was itself unverified.
05 / What to do now
- Treat unexpected calls, SMS, WhatsApp messages or emails that quote your loan, account or KYC details with suspicion. Never share an OTP, card PIN, UPI PIN or password, and do not install screen-sharing apps at a caller's request.
- Check your account and UPI history. Report any debit you do not recognise to the bank at once, using only contact details from its official website, bankofbaroda.bank.in, or your passbook.
- If you lose money, call the national cyber-fraud helpline 1930 immediately and file a complaint at cybercrime.gov.in; the faster a fraud is reported, the better the chance of stopping the money moving on.
- Ignore offers from anyone claiming they can remove your data from the dark web for a fee.
- Organisations: CERT-In's 2022 directions list unauthorised access to IT systems or data, data breaches and data leaks among incidents that must be reported within six hours, to incident@cert-in.org.in. Against email compromise, enforce phishing-resistant multi-factor authentication, audit mailbox forwarding rules and limit the customer documents that routinely travel by email.
Source log / 2026-0728-BB
- Bank of Baroda — Disclosure under Regulation 30 of SEBI (LODR): cyber-security incident (27 July 2026) Primary
- Bank of Baroda — Response to NSE clarification on dark-web data leak report (28 July 2026) Primary
- The Record — India's Bank of Baroda confirms cyber incident after hackers claim data theft (28 July 2026) Secondary
- Moneylife — Bank of Baroda says cyber incident stemmed from business email compromise (28 July 2026) Secondary
- Gulf News — Bank of Baroda data leak: what we know so far (27 July 2026) Secondary
- CERT-In — Directions under section 70B(6) of the IT Act, 2000 (28 April 2022) Primary